What exists,
counted.

The register narrates the build. This page counts it. Every number below is generated from the working tree and from two real runs — a forced turbo run test and a pnpm verify — by deploy/build-snapshot.mjs. Nothing here is authored, and no figure is carried forward from a previous day.

Commit 7d09274 Generated 2026-08-21 Scope packages · services · apps · tests Excluded spikes/ — prototype area, not deployable
14
Built
packages holding an implementation
20
Slots
boundary descriptor and nothing else
36,263
Source lines
excluding tests and blank lines
1,027
Tests
in 92 files
0
Failing
at package level — see the chain

The Release chain

pnpm verify stops at test:nfr-gov-001, and that is the correct result. The binding-NFR suites have no subject — there is no operator surface, no audit store, no credit ledger and no deployed probe fleet — so they fail, and they are written to fail against an absent implementation rather than pass vacuously. A suite that went green here would have stopped being able to see, which is why D-08 §5.3 makes a green shadow lane a failed Release. Do not read the red below as a defect.

  1. PASSinstall --frozen-lockfile1.2s
  2. PASScodegen:check0.7s
  3. PASStypecheck1.0s
  4. PASSlint6.6s
  5. PASSmigrate:check3.3s
  6. PASSbuild1.1s
  7. PASStest20.4s
  8. FAILtest:nfr-gov-0011.8s

Cited by NFR-GOV-001 · binding at every Release · SPK-02 §6.1–6.2, R9

Preconditions unmet at the failing suite: audit-store independent-verifier operator-identity-domain operator-surface subject-definition-ratified

Standing checks: 10 checks over 551 files, 0 violations.

Inventory — 34 packages

Package LinesTest filesTests
built services/runtime-orchestrator 14,729 17 338
built services/manifest-compiler 4,779 3 59
built services/identity-tenant 3,475 8 135
built services/model-gateway 2,546 6 70
built packages/manifest-semantic 2,065 4 52
built services/operator-governance 1,578 7 40
gate tests/nfr-fin-001Release gate. The 34 tests counted here are this suite's own unit tests. Its suite task — the gate — is RED and must stay RED until it has a subject. 1,378 3 34
gate tests/nfr-gov-001Release gate. The 39 tests counted here are this suite's own unit tests. Its suite task — the gate — is RED and must stay RED until it has a subject. 927 3 39
gate tests/nfr-sec-001Release gate. The 48 tests counted here are this suite's own unit tests. Its suite task — the gate — is RED and must stay RED until it has a subject. 863 6 48
built packages/manifest-canonical 837 4 49
built apps/tenant-webIts descriptor still declares a layout slot — no canvas is built. The vertical slice was built in the same package beside it. 763 2 13
gate tests/nfr-avl-001Release gate. The 38 tests counted here are this suite's own unit tests. Its suite task — the gate — is RED and must stay RED until it has a subject. 695 4 38
built packages/manifest-schema 633 3 16
built packages/effect-vocabulary 503 2 49
slot apps/public-write-apipublicThe narrow write path from the public domain into Control Plane services: signup, email verification and enquiry submission, and no other operation. 36 1 4
slot packages/api-client-operatorGenerated client for the operator OpenAPI artefact. 26 1 3
slot packages/api-client-tenantGenerated client for the tenant OpenAPI artefact. 25 1 3
slot services/billing-invoicingtenant · operatorOwns the invoicing half of the Credits and commerce API domain — issue, void, credit-note and settle invoices, with tax, payments, dunning and revenue recognition (§29.1, §26.4) — and the monthly availability determination of FR-BIL-019, which §33.1 places here because every input it reads is already this service’s own. 25 1 2
slot services/catalogue-registrytenant · operatorOwns the Catalogue API domain — search, retrieve, compare, use, configure, fork, publish and deprecate reusable Agents, Pods, Crew Templates and Packs (§29.1) — together with the publisher onboarding, verification and emergency unpublish controls the Catalogue Governor exercises (§6, FR-CAT-012). 25 1 2
slot services/credit-ledgertenant · operatorOwns the credit half of the Credits and commerce API domain — retrieve balance, runway and lots; reserve, extend, settle and release; grant, debit and expire credits; and retrieve, simulate, publish and pin rate card versions (§29.1, §26.1). 25 1 2
slot services/estate-telemetry-receiveroperatorReceives the report-only, outbound-initiated estate telemetry that FR-TEN-015 registers and FR-PLT-002 reports on, acknowledging a sequence position and issuing no instruction, configuration, query or command back to the estate (D-08 §2.13, SPK-09 §1.4). 25 1 2
slot services/evaluationtenantOwns the Evaluations API domain — run suites, compare results, retrieve failures and set Release thresholds (§29.1) — across the evaluation levels of §23.1 and the correction flywheel of §23.2. 25 1 2
slot services/human-tasktenantOwns the Approvals API domain — list assignments, retrieve context, approve, reject, edit, request revision and delegate (§29.1) — and the progressive autonomy and review sampling that governs when human review may be reduced (§22.2). 25 1 2
slot services/knowledge-retrievaltenantOwns the Knowledge API domain — create sources, ingest, test retrieval, refresh, delete and inspect Evidence (§29.1) — and the evidence sufficiency floor beneath which a Crew returns a structured insufficiency result rather than speculating (§18.2). 25 1 2
slot services/observability-audittenant · operatorOwns the audit half of the Audit and usage API domain — search or export events and compliance reports (§29.1) — and the append-only audit record of the six immutable categories, whose integrity NFR-GOV-001 binds at every Release. 25 1 2
slot services/platform-operationsoperatorOwns the Operator platform operations API domain — cross-tenant and per-estate health, model provider status and spend, incidents and computed blast radius, feature flags with their kill switch and promotion, and quarantine (§29.1, §26.5). 25 1 2
slot services/release-deploymenttenantOwns the Releases and deployment API domain — prepare, approve, deploy, promote, canary, rollback and retrieve health (§29.1) — so that no production change occurs without a visible diff, validation, tests and an approved new Release. 25 1 2
slot services/studio-collabtenantOwns the Projects and Studio API domain — create Projects, save manifests, diff versions and run simulations (§29.1) — and the collaborative editing of the visual canvas, whose state is declared presentational and is never the source of truth (§10.2). 25 1 2
slot services/tool-action-gatewaytenantOwns the Tools and connectors API domain — register, test, grant, revoke and inspect invocations (§29.1) — enforcing the Tool and Action contract and its permissions in the gateway, outside model prompts (§20.1). 25 1 2
slot services/usage-meteringtenant · operatorOwns the usage and cost half of the Audit and usage API domain (§29.1), aggregating and reconciling the usage records written at the Model Gateway into per-tenant, per-alias and per-Pack consumption, cost and margin (§24.1, NFR-FIN-002). 25 1 2
slot services/vibe-buildertenantOwns the Vibe change-request path — request Vibe changes against a Project (§29.1) — at the supported request levels of §11.1, resolving every conversational change into a versioned manifest diff that no path may deploy without validation, tests and an approved new Release (§11). 25 1 2
slot apps/operator-weboperatorThe cross-tenant surface wGrow staff administer every tenant through, on its own registrable domain and its own identity issuer, unreachable from a tenant session. 20 1 3
slot apps/public-portalpublicEverything served before authentication at KrewOS.ai; it holds no tenant data and carries no tenant session. 20 1 3
slot packages/design-systemPresentational components shared by the tenant and operator applications. 15 1 3